Re: IPSEC help



Hi,

tcpdump shows only isakmp information , there is no information about esp and AH header.

08:05:55.761245 IP 202.70.87.123.isakmp > ws130173.corporate-access.com.isakmp: isakmp: phase 1 ? ident[E]
08:05:55.775403 IP 202.70.87.121 > 202.70.87.123: ICMP redirect ws130173.corporate-access.com to host ws130173.corporate-access.com, length 556
08:05:55.778172 IP 202.70.87.123.isakmp > ws130173.corporate-access.com.isakmp: isakmp: phase 1 ? ident[E]


Regards,
John

VANHULLEBUS Yvan <vanhu_bsd@xxxxxxxxxx> wrote: On Tue, Nov 20, 2007 at 08:46:28AM -0800, john decot wrote:
Hi,

I have change life time in both side i.e 28800 sec but unlucky again.

[
2007-11-20 20:27:31: ERROR: ignore information because ISAKMP-SA has not been established yet.

Do a tcpdump/wireshark and have a look at what's in that informational
message...



Yvan.

--
NETASQ
http://www.netasq.com



---------------------------------
Be a better sports nut! Let your teams follow you with Yahoo Mobile. Try it now.
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: rsh working intermittently
    ... No I do not fully know what tcpdump displays. ... First success, then ... That's the TCP header, with this one containing options which is why ... The next packet shown ...
    (linux.redhat)
  • pseudo-driver (*pr_input)
    ... I am writing a pseudo driver for a routing protocol that insert its header ... tcpdump: listening on fxp0 ... extern struct domain inetdomain; ...
    (freebsd-hackers)
  • Re: How do you find the header file you need?
    ... > I tried building libpcap and tcpdump from my Red Hat 7 RPMs. ... > When a header file is missing, ... However normally if a header is missing, that means that the body of code ...
    (comp.lang.c)
  • Re: TG3 data corruption (TSO ?)
    ... I think we need those tcpdump after all. ... header is constructed by the tg3 in this case, ... I'm theorizing that this same failure can happen with TSO off as well, ...
    (Linux-Kernel)
  • tcpdump confused with NAT-T+IPSec Packets
    ... I'm using 2.6.11.7 and debugging why my ESP tunnel mode does ... tcpdump will display an incoming NAT-T packet after it ... incoming skb is being modified in place. ... Can't do it in ESP or UDP code because we can't tell if these packets ...
    (Linux-Kernel)